From 16717a555695ef666e9d2cd1bacc762a2ab15f4b Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Mon, 21 Sep 2026 23:53:58 -0300 Subject: Fixes from three adversarial reviews, and a destructive one among them The registry sweep could delete a live socket, anywhere on the filesystem. A reviewer reproduced it: a socket that is bound but has not reached listen(2) answers ECONNREFUSED exactly like a dead one -- that window is every server's startup -- and the sweep then followed the entry's symlink and unlinked whatever absolute path it named. It now follows a target only into the directory our own sockets live in and only to a `pardes-9p-*.sock` name, it re-probes immediately before deleting rather than trusting a probe that is by then several syscalls old, and a readlink that exactly filled its buffer is treated as the truncation it is. The test grew a case for an entry whose target is not ours: the entry goes, the file does not. Ctrl-V in raw tty mode was a black hole when the yank register was empty -- neither typed nor forwarded -- so vim's visual block, readline's quoted-insert and every other program's Ctrl-V simply vanished. With nothing to paste the chord belongs to the program again. The lone-ESC flush added earlier was dead code. vaxis already returns Escape for a one-byte 0x1b (`Parser.parseGround` asserts `input.len == 1`), so the carried byte it waited for can never exist; a reviewer showed a 3 ms gap and a 60 ms gap behaving identically. Removed rather than left to imply a guarantee it never provided. A shell whose editor is gone can start one again. Naming a live but unreachable session made `pardes ` exit 1, which let a stale environment variable lock someone out of their own editor; it falls through to an ordinary session, as it did before the variable existed. Also: the macOS ABI check for `pardes_topbar_pane_border_px` had been replaced by a duplicate of the line above it; `--startup` now fails on a leak the way every other measurement in that file does, and stops calling its maximum a p95 below twenty samples; the served README and the skill no longer tell you to write to `data` with `>`, which truncates the whole body before the write lands; `docs/v9fs.md` described the allocate-on-walk design that was rejected; and `test/fs.py` keys nesting off `PARDES_PID`, so its forwarding case stops passing only when the runner happens to be inside a live pardes. fs-test now reaches its one documented pre-existing failure instead of dying early. Suite 778/783 with the two known crashes. Co-Authored-By: Claude Opus 5 (1M context) --- src/tty/tty.zig | 31 ------------------------------- 1 file changed, 31 deletions(-) (limited to 'src/tty') diff --git a/src/tty/tty.zig b/src/tty/tty.zig index a1917ba9..23b7c09b 100644 --- a/src/tty/tty.zig +++ b/src/tty/tty.zig @@ -71,21 +71,6 @@ fn inputReader(loop: *Loop, tty: anytype, cache: *vaxis.GraphemeCache) void { loop.postEvent(.quit) catch {}; } -/// How long a lone ESC waits for the rest of a sequence before it counts as -/// the Escape key. Long enough for the remainder of a real sequence to arrive -/// even over a slow link, short enough that nobody sees the delay. -const escape_hold_ms = 25; - -/// Is there more input right behind what we have already read? Only a real -/// terminal has an fd to ask; the test readers hand their parts over whole, so -/// for them the answer is always no. -fn morePending(tty: anytype) bool { - const Reader = @typeInfo(@TypeOf(tty)).pointer.child; - if (!@hasField(Reader, "fd") or @FieldType(Reader, "fd") != std.Io.File) return false; - var fds = [_]std.posix.pollfd{.{ .fd = tty.fd.handle, .events = std.posix.POLL.IN, .revents = 0 }}; - return (std.posix.poll(&fds, escape_hold_ms) catch return false) > 0; -} - fn readInput(loop: *Loop, tty: anytype, cache: *vaxis.GraphemeCache) !void { try loop.postEvent(.{ .winsize = try tty.getWinsize() }); var parser: vaxis.Parser = .{}; @@ -116,22 +101,6 @@ fn readInput(loop: *Loop, tty: anytype, cache: *vaxis.GraphemeCache) !void { } carried = end - consumed; std.mem.copyForwards(u8, buf[0..carried], buf[consumed..end]); - // A lone ESC opens most sequences and is also the Escape key, so the - // parser holds it for a remainder that a keypress never sends: the - // press would only land when the NEXT key arrived. Wait a beat, and - // when nothing follows it was the key. A terminal speaking the kitty - // protocol never reaches here — it spells Escape out in full. - if (carried == 1 and buf[0] == 0x1b and !morePending(tty)) { - carried = 0; - try vaxis.loop.handleEventGeneric( - loop, - loop.vaxis, - cache, - @TypeOf(Command.value), - @as(vaxis.Event, .{ .key_press = .{ .codepoint = vaxis.Key.escape } }), - loop.vaxis.opts.system_clipboard_allocator, - ); - } } } -- cgit v1.3